A network illegal transaction relationship prediction method and system based on association rules
By constructing a dataset and using association rules to calculate coded messages, the problem of coded message identification in illegal online transactions was solved, enabling accurate identification and quantification of transaction relationships and improving the law enforcement capabilities.
Patent Information
- Application Number
- CN202410846429.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-27
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-06-27
AI Technical Summary
Illegal traders use coded language in online communication software to conduct transactions, resulting in secret chat logs that make it difficult to quickly identify and recognize illegal online transaction relationships.
By collecting chat logs of suspected online illegal transactions, preprocessing the text, constructing a dataset, calculating word association degree using association rules, obtaining coded language between the transacting parties, performing semantic similarity calculation and communication activity analysis, and identifying potential suspects and their relationship networks.
It effectively identifies coded messages in the transaction process, improves the efficiency and accuracy of identifying illegal online transactions, significantly enhances the crackdown capabilities of law enforcement agencies, has strong adaptability and scalability, and can quantify the closeness of transaction relationships.
Smart Images

Figure CN119670719B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information text analysis technology, and in particular to a method and system for predicting illegal online transaction relationships based on association rules. Background Technology
[0002] With the increasing popularity of the internet and online chat tools, a vast number and variety of illegal goods and services have emerged online. Online illegal transactions differ from traditional offline illegal transactions in that they are more covert in their methods and channels, involve more people, and span a wider geographical area. Related illegal transactions have undergone significant changes in terms of transaction methods, payment methods, and transportation methods.
[0003] When conducting illegal online transactions, perpetrators often use instant messaging tools such as WeChat and QQ, or email and other communication software to complete the transactions. To avoid suspicion from online chat records, illegal merchants and their counterparts frequently use coded language to refer to sensitive words in the transactions. To more accurately identify whether an illegal transaction has occurred, correlation rules can be used to identify potential coded language. By calculating the text similarity of the suspect's chat records across various chat software, potential counterparties who may be engaging in illegal transactions with the suspect can be identified. Summary of the Invention
[0004] In view of the problems existing in the existing methods for predicting illegal online transaction relationships based on association rules, this invention is proposed.
[0005] Therefore, the problem that this invention aims to solve is that illegal traders use coded language when conducting illegal transactions through online communication software, making the chat records of these transactions secret and difficult to identify quickly.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, embodiments of the present invention provide a method for predicting the relationship of illegal online transactions based on association rules. The method includes: collecting relevant intelligence information of suspects in illegal online transactions and performing text preprocessing to create a dataset; based on the dataset, calculating the degree of association between words and marked words in the dataset to obtain coded language in the communication process between the two parties in the transaction; based on the obtained coded language, performing semantic similarity calculation to determine potential suspects, and determining whether they are potential core personnel based on the level of communication activity to determine the network of relationships between individuals.
[0008] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, the preprocessing includes: data cleaning: including removing stop words and performing Chinese word segmentation; feature extraction: preparing a relevant dictionary for the current illegal transaction field, retaining and extracting special words and proper nouns; separating and statistically analyzing the chat records between the suspect and the contact according to the communication time, considering communication records with an interval not exceeding a certain limit as one communication, and statistically analyzing the relevant words and their frequencies in each communication; dividing the communication information of each contact into a separate data group, containing word c i Word frequency f i Frequency of communication t m Average time interval x m ; Based on the suspect's vocabulary and phrases, and combined with a dictionary of illegal transactions, another dataset was constructed, including the word 'a'. i Word frequency f i ';The resulting multiple data sets g k and data group g k 'Construct datasets G and G' separately.
[0009] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, wherein: the data group g k Represented as:
[0010] g k ={(c1,f1)...(c i ,f i ...(c j ,f j ), t m ,x m}
[0011] Where j, m ∈ N, N is the set of natural numbers, c i Words indicating contact persons, f i c i word frequency, t m Indicates the frequency of communication between contacts, x m This represents the average time interval between two exchanges; g k Create a dataset G, represented as:
[0012] G = {g1,...g} k ,...g n}
[0013] Where n represents the number of contacts the suspect has.
[0014] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, wherein: the data group g'k Represented as:
[0015] g' k ={(a1,f'1)...(a i ,f i ')...(a j ,f j '), t' m ,x m}
[0016] Among them, a i Words indicating suspect, f' i Indicates a i word frequency; t' m Indicates the frequency of communication between the suspects; g' k Create a dataset G', represented as:
[0017] "'
[0018] G={g k1 ,...g kn}
[0019] Furthermore, a i Including contact vocabulary c i And the corresponding domain dictionary for word b, if there exists word c∈a i But not ∈ c i The corresponding word f i According to the remaining c i The average value is calculated from the top p% of the highest word frequencies.
[0020] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, the method involves: obtaining coded messages from the communication process based on the dataset G by using the Apriori algorithm to calculate the degree of association between words in dataset G and words in the suspect's vocabulary set G', discovering coded messages based on the calculation results, and updating and compiling a new illegal vocabulary dictionary; the coded messages are determined by lift, expressed by the formula:
[0021]
[0022]
[0023] The mined cryptic terms are scored based on their lift levels. The distribution of values from word frequency, support, and confidence scores is considered, and a suitable minimum value θ is selected based on practical experience. If the score w of the cryptic term... i If the score is ≤θ, then words with scores below the threshold will be deleted, and the data subset g to which the person belongs will be considered. k Update to g i={(c1,f1,w1)...(c i ,f i ,w i ...(c j ,f j ,w j ), t m ,x m}, update g' k g' k ={(a1,f'1,w1)...(a i ,f' i ,w i ...(a j ,f j ',w j ), t' m ,x m}
[0024] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, the method includes: performing similarity judgment based on the coded language, normalizing the data, and using... As one of the vector components Let f be the average value of the corresponding word in all user data g; then the content similarity calculation is expressed as:
[0025]
[0026] Where f represents the word frequency f of all words c, and g includes g' k and g k .
[0027] As a preferred embodiment of the network illegal transaction relationship prediction method based on association rules described in this invention, a similarity matrix is obtained based on the calculation of content similarity, and is represented as follows:
[0028]
[0029] Based on the numerical values in the similarity matrix, the maximum inter-class variance method, adaptive thresholding, and histogram analysis are selected. Appropriate standard minimum threshold λ and maximum threshold μ are calculated. If they exist:
[0030]
[0031] Then there exists g j 'with g k 'The topics are different; otherwise, they are considered to have the same topic. The corresponding data is then divided into three parts: topics related to illegal transactions, topics unrelated to illegal transactions, and topics for which the topic cannot be determined. If g exists...' i and g'i If they belong to the same category, it is determined that the suspect and the person in the conversation engaged in a dialogue regarding the illegal and criminal transaction; based on the s obtained in the previous step... i,j Further calculation of the level of activity p of the two parties in engaging in illegal transactions i , is represented as:
[0032]
[0033] Based on the transaction activity between the suspect and his contacts p i And whether there are downstream buyers to determine whether someone is an intermediary, the activity criterion is set as β, which is expressed as:
[0034]
[0035] If s i,j <λ,p i If the value is greater than β, it indicates high topic activity and the individual may be a middleman; if s i,j <λ,p i If ≤β, the topic is considered highly relevant, but the activity level is low, suggesting the buyer may be a latecomer; if s i,j ≥λ, p i If the value is >β, it indicates that the topic has low relevance but high activity, and the person may be a relative or friend of the suspect.
[0036] Secondly, embodiments of the present invention provide a network illegal transaction relationship prediction system based on association rules, comprising: a collection module for collecting relevant intelligence information of network illegal transaction suspects, performing text preprocessing, and creating a dataset; a calculation module for calculating the degree of association between words and marked words in the dataset based on the dataset, and obtaining coded language in the communication process between the two parties in the transaction; and a judgment module for performing semantic similarity calculation based on the obtained coded language to judge potential suspects, and judging whether they are potential core personnel based on the level of communication activity, thereby determining the network of relationships between individuals.
[0037] Thirdly, embodiments of the present invention provide a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement any step of the above-described method for predicting illegal online transaction relationships based on association rules.
[0038] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the above-described method for predicting illegal network transaction relationships based on association rules.
[0039] The beneficial effects of this invention are that it can effectively identify coded language used in transactions, overcoming the difficulties in identifying illegal transactions caused by coded language, and objectively quantifying the closeness of transaction relationships through mathematical models. This significantly improves the efficiency and accuracy of law enforcement agencies in detecting and combating illegal online transactions, providing strong technical support for cybersecurity supervision. Furthermore, it has strong adaptability and scalability, allowing for adjustments and optimizations based on different types of illegal transactions, and has significant practical significance and application value for maintaining cyberspace order, combating cybercrime, and protecting public interests. Attached Figure Description
[0040] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:
[0041] Figure 1 This is a flowchart of the present invention;
[0042] Figure 2 This is a logical diagram illustrating the construction of a network of illegal transaction relationships. Detailed Implementation
[0043] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0044] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0045] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0046] Example 1
[0047] Reference Figure 1 and Figure 2This is the first embodiment of the present invention, which provides a method for predicting illegal online transaction relationships based on association rules, including:
[0048] S1: Collect relevant intelligence information on suspects involved in illegal online transactions, preprocess the text, and generate data.
[0049] Preprocessing includes:
[0050] Data cleaning includes removing stop words and performing Chinese word segmentation;
[0051] Feature extraction: Prepare a dictionary targeting the current illegal transaction field, and retain and extract special words and proper nouns;
[0052] The chat logs between the suspect and the contact were analyzed separately according to the time of the communication. Communication records with a time interval not exceeding a certain limit were regarded as one communication. The relevant words and their frequencies in each communication were counted.
[0053] The communication information for each contact is divided into a separate data group, containing vocabulary c. i Word frequency f i Frequency of communication t m Average time interval x m ;
[0054] Based on the suspect's vocabulary and phrases, and combined with a dictionary of illegal transactions, another dataset was constructed, including the word "a". i Word frequency f i ';
[0055] The obtained multiple data sets g k and data group g k 'Construct datasets G and G' separately.
[0056] S2: Based on the dataset, calculate the degree of association between words in the dataset and the marked words to obtain the coded language in the communication process between the two parties in the transaction.
[0057] Data set g k Represented as:
[0058] g k ={(c1,f1)...(c i ,f i ...(c j ,f j ), t m ,x m}
[0059] Where j, m ∈ N, N is the set of natural numbers, c i Words indicating contact persons, f i c iword frequency, t m Indicates the frequency of communication between contacts, x m This represents the average time interval between two exchanges;
[0060] g k Create a dataset G, represented as:
[0061] G = {g1,...g} k ,...g n}
[0062] Where n represents the number of contacts the suspect has.
[0063] Data set g' k Represented as:
[0064] g' k ={(a1,f'1)...(a i ,f i ')...(a j ,f j '), t' m ,x m}
[0065] Among them, a i Words indicating suspect, f i ' represents a i word frequency; t' m Indicates the frequency of communication between the suspects;
[0066] g' k Create a dataset G', represented as:
[0067] "'
[0068] G={g k1 ,...g kn}
[0069] Furthermore, a i Including contact vocabulary c i And the corresponding domain dictionary for word b, if there exists word c∈a i But not ∈ c i The corresponding word f i According to the remaining c i The average value is calculated from the top p% of the highest word frequencies.
[0070] S3: Based on the acquired coded messages, similarity calculations are performed to identify potential suspects, and at the same time, the frequency of communication is used to identify key personnel.
[0071] The acquisition of coded messages in communication processes based on the dataset G involves using the Apriori algorithm to calculate the correlation between words in dataset G and words in the suspect's vocabulary set G'. Based on the calculation results, coded messages are discovered, and a new dictionary of illegal vocabulary is updated and compiled. Codes are determined by lift, expressed by the following formula:
[0072]
[0073]
[0074] The discovered cryptic messages are scored based on their degree of elevation, and a suitable minimum value θ is selected based on the calculation results.
[0075] If the score of the cryptic vocabulary is w i If the score is ≤θ, then words with scores below the threshold will be deleted, and the data subset g to which the person belongs will be considered. k Update to: g i ={(c1,f1,w1)...(c i ,f i ,w i ...(c j ,f j ,w j ), t m ,x m}, update g' k g' k ={(a1,f'1,w1)...(a i ,f' i ,w i ...(a j ,f j ',w j ), t' m ,x m}
[0076] Determining whether two things are related includes:
[0077] Determine if the support score is greater than the minimum support threshold;
[0078] Find all frequent itemsets, generate association rules, calculate confidence scores, and exclude rules with confidence scores below the minimum confidence threshold.
[0079] In short, support refers to the probability that things a and b occur simultaneously; confidence represents the probability that thing b occurs given that thing a has occurred; and lift is the ratio of their probability.
[0080] This is used to extract terms related to illegal transactions in this field from the disorganized raw data by comparing them with a subset of known terms related to illegal transactions in this field. These terms are called "code words".
[0081] The core of the Apriori algorithm is what the above three expressions represent. The disadvantage of this algorithm is that the data is mixed and the computational redundancy in the iteration process is large. To reduce the complexity of the iteration process, certain grouping and data filtering and matching methods are adopted.
[0082] Similarity is determined based on the cryptic language, since f i The corresponding numerical part is greater than w i The corresponding values are then normalized using... As one of the vector components The average value of f for the corresponding word across all user data g;
[0083]
[0084] Where f represents the word frequency f of all words c, and g includes g' k and g k .
[0085] S4: Create a core dataset based on relevant intelligence information of key personnel, determine whether a transaction is a real entity based on the core dataset, and extract relevant information from the core dataset to predict and intercept transactions.
[0086] The core dataset includes: types and characteristics of illegal online transactions, as well as address information contained in related intelligence.
[0087] Based on the calculation of content similarity, a similarity matrix is obtained, which is represented as follows:
[0088]
[0089] Based on the values in the matrix, select appropriate standard minimum threshold λ and maximum threshold μ. If they exist:
[0090]
[0091] Then there exists g j 'with g k If the topics are different, then the topics are considered to be the same.
[0092] The corresponding data is then divided into three parts: topics related to illegal transactions, topics unrelated to illegal transactions, and topics for which the topic cannot be determined.
[0093] If g exists i as well as' iIf they belong to the same category, it is determined that the suspect and the person they were talking to had engaged in a conversation about the illegal and criminal transaction.
[0094] Based on the s obtained in the previous step i,j Further calculation of the level of activity p of the two parties in engaging in illegal transactions i , is represented as:
[0095]
[0096] Based on the trading activity level p of both parties i And whether there are downstream buyers to determine whether someone is an intermediary, the activity criterion is set as β, which is expressed as:
[0097]
[0098] If s i,j <λ,p i If the value is >β, it indicates a high level of topic activity, suggesting the individual may be a middleman.
[0099] If s i,j <λ,p i If the value is ≤β, the topic is considered to be highly relevant, but the activity level is low, and the buyer may be a latecomer.
[0100] If s i,j ≥λ, p i If the value is >β, it indicates that the topic has low relevance but high activity, and the person may be a relative or friend of the suspect.
[0101] The middleman is the core of the next step in the calculation; they are new suspects, the axis of the transaction network, and also a member of the key personnel. Key personnel include a large number of downstream traders and upstream or downstream trading agents, identified by the frequency of their contact and the presence of upstream and downstream intermediaries.
[0102] In summary, this invention can effectively identify coded language used in transactions, overcoming the difficulties in identifying illegal transactions caused by coded language, and can also objectively quantify the closeness of transaction relationships through mathematical models. This significantly improves the efficiency and accuracy of law enforcement agencies in detecting and combating illegal online transactions, providing strong technical support for cybersecurity supervision. Furthermore, it has strong adaptability and scalability, and can be adjusted and optimized according to different types of illegal transactions, making it of significant practical importance and application value for maintaining cyberspace order, combating cybercrime, and protecting public interests.
[0103] Example 2
[0104] Reference Figure 1Based on the first embodiment, this embodiment further provides a network illegal transaction relationship prediction system based on association rules, including:
[0105] The collection module is used to collect intelligence information related to suspects of illegal online transactions, perform text preprocessing, and create a dataset.
[0106] The calculation module is used to calculate the degree of association between words and marked words in the dataset based on the dataset, and to obtain the coded language in the communication process between the two parties in the transaction;
[0107] The judgment module is used to perform semantic similarity calculations based on the acquired coded messages to identify potential suspects, and to determine whether they are potential core personnel based on the level of communication activity, thereby identifying the relationship network of the individuals.
[0108] This embodiment also provides a computer device applicable to the method for predicting illegal online transaction relationships based on association rules, including a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for predicting illegal online transaction relationships based on association rules as proposed in the above embodiment.
[0109] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0110] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the method for predicting illegal network transaction relationships based on association rules as proposed in the above embodiments.
[0111] The storage medium proposed in this embodiment and the data storage method proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0112] Example 3
[0113] Based on the previous two embodiments, this embodiment provides a method for predicting illegal online transaction relationships based on association rules. To verify the beneficial effects of the present invention, a simulation experiment is conducted for scientific demonstration.
[0114] To fully verify the effectiveness of the method of this invention, a series of in-depth simulation experiments were conducted, and a multi-dimensional comparison was made with three existing methods, including the traditional keyword matching method, the machine learning-based text classification method (SVM), and the deep learning-based LSTM (Long Short-Term Memory) network method.
[0115] The experimental data consisted of 1,000 samples of real network communication records obtained by a law enforcement agency, including 200 confirmed illegal transactions and 800 ordinary transactions. All samples underwent anonymization to protect privacy.
[0116] The experimental setup includes:
[0117] Traditional keyword matching method: Matching is performed using a predefined list of keywords related to illegal transactions.
[0118] Machine learning-based text classification: using the Support Vector Machine (SVM) algorithm, trained and classified with TF-IDF features.
[0119] Deep learning-based LSTM network method: Sequence classification using pre-trained word embedding models and LSTM networks.
[0120] Evaluation indicators include:
[0121] Accuracy;
[0122] Precision;
[0123] Recall rate;
[0124] F1 score;
[0125] AUC-ROC (Area Under the Curve-Receiver Operating Characteristic);
[0126] Hidden language recognition rate;
[0127] Accuracy of constructing interpersonal relationship networks.
[0128] The experimental results are shown in Table 1:
[0129] Table 1 Comparative Experiment Results Data Table
[0130]
[0131] As shown in Table 1, the method of this invention significantly outperforms other methods in all four basic metrics: accuracy, precision, recall, and F1 score, especially excelling in handling complex illegal transaction samples. Furthermore, the AUC-ROC value of this method reaches 0.968, approaching perfect classification, indicating that it maintains excellent classification performance across different thresholds.
[0132] This method demonstrates strong adaptability when dealing with novel coded language. In the test set, 20 samples using novel coded language were specifically added, and this method successfully identified 17 of them, while other methods identified a maximum of only 12.
[0133] This method has a more obvious advantage when constructing large-scale interpersonal relationship networks. In a simulation of a large illegal transaction network with 100 nodes, this method successfully restored 88% of the network structure, while other methods only achieved a maximum of 80%.
[0134] Through this comprehensive simulation experiment, we can clearly see that the method of this invention significantly outperforms existing technologies in several key indicators. It not only improves the accuracy and comprehensiveness of illegal transaction identification but also demonstrates powerful capabilities in coded language recognition and the construction of interpersonal relationship networks. These results fully demonstrate the enormous potential of the method of this invention in practical applications and are of great significance for enhancing the supervision and crackdown capabilities on illegal online transactions.
[0135] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for predicting illegal online transaction relationships based on association rules, characterized in that: include, Collect intelligence information related to suspects involved in illegal online transactions, perform text preprocessing, and create a dataset. Based on the dataset, the degree of association between words in the dataset and marked words is calculated to obtain the coded language in the communication process between the two parties in the transaction; Based on the acquired coded messages, semantic similarity calculations are performed to identify potential suspects, and the level of communication activity is used to determine whether they are potential core personnel, thus identifying the network of relationships between individuals. Preprocessing includes: Data cleaning includes removing stop words and performing Chinese word segmentation; Feature extraction: Prepare a dictionary targeting the current illegal transaction field, and retain and extract special words and proper nouns; The chat logs between the suspect and the contact were analyzed separately according to the time of the communication. Communication records with a time interval not exceeding a certain limit were regarded as one communication. The relevant words and their frequencies in each communication were counted. The communication information for each contact is divided into a separate data group, containing vocabulary c. i Word frequency f i Frequency of communication t m Average time interval x m ; Based on the suspect's vocabulary and phrases, and combined with a dictionary of illegal transactions, another dataset was constructed, including the word "a". i Word frequency f i '; The obtained multiple data sets g k and data group g k 'Construct datasets G and G' separately; The acquisition of coded messages in communication processes based on the dataset G involves using the Apriori algorithm to calculate the correlation between words in dataset G and words in the suspect's vocabulary set G'. Based on the calculation results, coded messages are discovered, and a new dictionary of illegal vocabulary is updated and compiled. Codes are determined by lift, expressed by the following formula: Support Confidence Improvement The extracted cryptic phrases are scored according to their different degrees of elevation. The numerical distribution of the calculated results of word frequency, support, and confidence is combined with practical application experience to select an appropriate minimum value θ. If the score of the cryptic vocabulary is w i If the score is ≤θ, then words with scores below the threshold will be deleted, and the data subset g to which the person belongs will be considered. k Update to g i ={(c1,f1,w1)...(c i ,f i ,w i ...(c j ,f j ,w j ), t m ,x m }, Update g' k g' k ={(a1,f'1,w1)...(a i ,f' i ,w i ...(a j ,f j ',w j ), t' m ,x m }; Similarity is determined based on the cryptic language, and the data is normalized. As one of the vector components Let f be the average value of the corresponding word across all user data g; then the content similarity calculation is expressed as: Where f represents the word frequency f of all words c, and g includes g' k and g k ; Based on the calculation of content similarity, a similarity matrix is obtained, which is represented as follows: Based on the numerical values in the similarity matrix, the maximum inter-class variance method, adaptive thresholding, and histogram analysis are selected. Appropriate standard minimum threshold λ and maximum threshold μ are calculated. If they exist: Then there exists g j 'with g k 'The topics are different; otherwise, the topics are considered to be the same.' The corresponding data is then divided into three parts: topics related to illegal transactions, topics unrelated to illegal transactions, and topics for which the topic cannot be determined. If g exists i and g' i If they belong to the same category, it is determined that the suspect and the other party in the conversation had engaged in a dialogue regarding the illegal transaction; Based on the s obtained in the previous step i,j Further calculation of the level of activity p of the two parties in illegal transactions i , is represented as: Based on the transaction activity between the suspect and his contacts p i And whether there are downstream buyers to determine whether someone is an intermediary, the activity criterion is set as β, which is expressed as: If s i,j <λ,p i If the value is >β, it indicates a high level of topic activity, suggesting the individual may be a middleman. If s i,j <λ,p i If the value is ≤β, the topic is considered to be highly relevant, but the activity level is low, and the buyer may be a latecomer. If s i,j ≥λ, p i If the value is >β, it indicates that the topic has low relevance but high activity, and the person may be a relative or friend of the suspect.
2. The method for predicting illegal online transaction relationships based on association rules as described in claim 1, characterized in that: The data group g k Represented as: g k ={(c1,f1)...(c i ,f i )...(c j ,f j ),t m ,x m } Where j, m ∈ N, N is the set of natural numbers, c i Words indicating contact persons, f i c i word frequency, t m Indicates the frequency of communication between contacts, x m This represents the average time interval between two exchanges; g k Create a dataset G, represented as: G={g1,...g k ,...g n } Where n represents the number of contacts the suspect has.
3. The method for predicting illegal online transaction relationships based on association rules as described in claim 2, characterized in that: The data group g' k Represented as: to k ={(a1,f'1)...(a i ,f i ')...(a j ,f j '),t' m ,x m } Among them, a i Words indicating suspect, f' i Indicates a i word frequency; t' m Indicates the frequency of communication between the suspects; g' k Create a dataset G', represented as: G′={g′ k1 ,...g′ kn } Furthermore, a i Including contact vocabulary c i And the corresponding domain dictionary for word b, if there exists word c∈a i But not ∈ c i The corresponding word f i According to the remaining c i The average value is calculated from the top p% of the highest word frequencies.
4. A network illegal transaction relationship prediction system based on association rules, based on the network illegal transaction relationship prediction method based on association rules as described in any one of claims 1 to 3, characterized in that: include, The collection module is used to collect intelligence information related to suspects of illegal online transactions, perform text preprocessing, and create a dataset. The calculation module is used to calculate the degree of association between words and marked words in the dataset based on the dataset, and to obtain the coded language in the communication process between the two parties in the transaction; The judgment module is used to perform semantic similarity calculations based on the acquired coded messages to identify potential suspects, and to determine whether they are potential core personnel based on the level of communication activity, thereby identifying the relationship network of the individuals.
5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the network illegal transaction relationship prediction method based on association rules as described in any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the network illegal transaction relationship prediction method based on association rules as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Group dividing method and system of communication network
CN102202012A
Commodity recommendation method and system based on social e-commerce platform, computer readable medium and device
CN110335123A